agent-send
Warn
Audited by Snyk on Mar 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's Multi-Agent Workflow and sendToAgent/sendToAgentAndWait examples in SKILL.md show the agent reading agentResponse and channel messages/attachments from Discord/Telegram/Slack (user-generated, untrusted platform content) and directly using that content to construct further messages and actions (e.g., passing research.agentResponse into a follow-up request), which could enable indirect prompt injection.
Audit Metadata